customized security/rights on servers

We have a request were an app support team needs to be able to start/stop windows services and install apps on their windows servers. We do not want to give them local admin rights. we running 2008 AD and all servers are win2008r2. What would be the best approach to solve this? Any advice/direction appreciated.